CWE-770
High likelihoodAllocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
2,071 vulnerabilities with CWE-770
CVE-2026-46673
HIGH
Russh < 0.60.3 CryptoVec - Unbounded Allocation Resource Exhaustion
CVSS 7.5
CVE-2026-45664
MEDIUM
ImageMagick: Policy Bypass in MNG coder could
CVSS 5.3
CVE-2026-45031
MEDIUM
ImageMagick: Policy Bypass in PSD decoder
CVSS 5.3
CVE-2026-10740
MEDIUM
Excessive memory allocation in s2n-quic
CVSS 5.3
CVE-2026-24720
MEDIUM
QNAP File Station 5 < 5.5.6.5243 - Resource Exhaustion
CVSS 6.5
CVE-2026-41726
MEDIUM
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
CVSS 6.5
CVE-2026-41716
HIGH
Spring Data web support unbounded negative-result cache keyed on attacker-supplied property names
CVSS 7.5
CVE-2026-28237
MEDIUM
Amd µProf - Allocation of Resources Without Limits or Throttling
CVSS 5.5
CVE-2026-49955
MEDIUM
Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options
CVSS 5.3
CVE-2026-45591
HIGH
Microsoft ASP.NET Core - Unauthenticated Denial of Service
CVSS 7.5
CVE-2026-42570
HIGH
Svelte devalue: DoS via sparse array deserialization
CVSS 7.5
CVE-2026-41851
MEDIUM
Spring Framework Denial of Service via Unbounded Cache in SpEL
CVSS 5.3
CVE-2026-41710
MEDIUM
Cache Exhaustion in Stateful Retries leads to Denial of Service
CVSS 5.9
CVE-2026-41007
HIGH
Spring HATEOAS heap exhaustion through unbounded internal caching
CVSS 7.5
CVE-2026-40984
HIGH
Micrometer HTTP server instrumentations DoS vulnerability
CVSS 7.5
CVE-2026-40983
HIGH
Micrometer gRPC server instrumentation DoS vulnerability
CVSS 7.5
CVE-2026-43973
HIGH
gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion
CVE-2026-45290
HIGH
Cloudburst Network has DoS in RakNet connection handling due to missing bound checks
CVSS 7.5
CVE-2026-50589
MEDIUM
Openstack Ironic < 35.0.1 - Allocation of Resources Without Limits or Throttling
CVSS 5.3
CVE-2026-40898
MEDIUM
quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion
CVSS 5.3
CVE-2026-36499
MEDIUM
Open vSwitch v3.6.90 - Denial of Service via Excessive Thread Allocation in udpif_set_threads()
CVSS 6.5
CVE-2026-44545
MEDIUM
Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of service
CVSS 5.3
CVE-2026-48597
HIGH
Atom table exhaustion via untrusted URL scheme in Tesla.Adapter.Mint
CVE-2026-35202
LOW
Pterodactyl Panel <1.12.3 Client API - Database Limit Bypass
CVE-2026-34077
HIGH
React Router vulnerable to Denial of Service via reflected user input in single-fetch
CVSS 7.5
Details
Vulnerabilities
2,071
Exploit Likelihood
High